You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何调用GetUserInfoAsync()时提示‘Bearer token not found’?

问题:GetUserInfoAsync调用提示Bearer token not found,IntrospectTokenAsync正常运行

用户代码如下:

var client = new HttpClient();
var firstResponse = await client.RequestPasswordTokenAsync(new PasswordTokenRequest
{
    Address = disco.TokenEndpoint,

    ClientId = "roclient.reference",
    ClientSecret = "secret",

    UserName = "bob",
    Password = "Pass123$",
    Scope = "resource1.scope1 resource2.scope1"
});


var result = await client.GetUserInfoAsync(new UserInfoRequest
{
    Address = disco.UserInfoEndpoint,

    ClientId = "api1",
    ClientSecret = "secret",
    Token = firstResponse.AccessToken
});

if (result.IsError)
{
    Console.WriteLine(result.Error);
}

运行后Identity Server端提示Bearer token not found,客户端返回Unauthorized,但相同的AccessToken在IntrospectTokenAsync()中可正常使用,需解决GetUserInfoAsync()正确传入AccessToken的问题。


解决方案

问题出在GetUserInfoRequest的参数设置上:

  • UserInfo端点的身份验证依赖AccessToken本身,不需要传入ClientId和ClientSecret。你额外添加这两个参数后,客户端会错误地尝试用客户端凭证模式发起请求,而不是把AccessToken放到Authorization头里作为Bearer令牌,导致服务端找不到Bearer token。

修正后的代码只需移除GetUserInfoRequest中的ClientId和ClientSecret:

var result = await client.GetUserInfoAsync(new UserInfoRequest
{
    Address = disco.UserInfoEndpoint,
    Token = firstResponse.AccessToken
});

这样客户端就会正确地将AccessToken以Bearer {token}的格式放到请求头中,UserInfo端点就能正常识别并验证令牌了。


内容的提问来源于stack exchange,提问作者user216652

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 17:17:11